Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Orion does use native Keychain for passwords (and also uses iCloud to sync them).


It uses its own separate keychain entries (whatever the term is), not the stuff that's used by the iOS system level functionality.


That is by design of Keychain, apps can not access each others keychain, otherwise it would not be secure. There is no "iOS system level keychain" but all apps use a bucket in keychain - Safari uses one and Orion uses one.


The design of “passwords” on the Mac and iOS doesn’t make it seem like anything is a “safari” password.

You save a password to the keychain in safari, and then you go to the “passwords” system preferences panel and you see those passwords. Or the other way around—creating a password from system preferences makes it accessible in browser. It appears on the surface to just be a password app, not a safari bucket.

It also works this way if you use the iCloud passwords app from windows. All of your saved passwords show up there as well, despite the absence of safari.

I’m pretty sure the new Chrome extension also shares your existing passwords.

I think it’s a reasonable assumption that when an app claims to use the keychain that you will have access to all your previously saved passwords.


Safari uses the Apple bucket, that is also exposed through the Apple's Chrome extension and also when you go to System preferences Passwords pane.

When you view passwords in Orion, you are also viewing passwords saved on Keychain, just in this case Orion's bucket.

There are various system API's that allow apps to read from each other's bucket (obviously all Apple apps have access to Apple's keychain bucket). This is how you can autofill passwords from different keychains in Orion (for example Apple's - which I call Safari's because this is how typically passwords land in it).


While I started this by giving you the plug .. the lack of it being the same password bucket combined with not getting 1Password to play nice, is what prevents me from making daily use, or rolling it out across my engineering employee base. I really like it otherwise.


Actually 1pw should be working properly now, after an extremely long time




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: